cbcvebase.
CVE-2021-36029
published 2021-09-01

CVE-2021-36029: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper improper authorization vulnerability…

PriorityP345high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
2.48%
82.6th percentile
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper improper authorization vulnerability. An attacker with admin privileges could leverage this vulnerability to achieve remote code execution.

Affected

10 ranges
VendorProductVersion rangeFixed in
adobeadobe_commerce
adobeadobe_commerce2.3.0 – 2.3.7
adobeadobe_commerce2.4.0 – 2.4.2
adobemagento_commerceunspecified – 2.4.2
adobemagento_open_source
adobemagento_open_source2.3.0 – 2.3.7
adobemagento_open_source2.4.0 – 2.4.2
magentocommunity-edition>= 0 < 2.3.7-p12.3.7-p1
magentocommunity-edition>= 2.4.2-p1 < 2.4.2-p22.4.2-p2
magentoproject-community-edition0 – 2.0.2

CVSS provenance

nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.